The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2020-18261: Unrestricted Upload of File with Dangerous Type9.8 CriticalN/A1%Nov 3, 2021
CVE-2020-18262: Improper Neutralization of Special Elements used in an SQL Command9.8 CriticalN/A1%Nov 3, 2021
CVE-2020-18259: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A1%Nov 3, 2021
CVE-2020-23680: Undefined Security Weakness7.8 HighN/A1%Nov 3, 2021
CVE-2020-23679: Buffer Copy without Checking Size of Input9.8 CriticalN/A2%Nov 3, 2021
CVE-2020-24000: Improper Neutralization of Special Elements used in an SQL Command9.8 CriticalN/A2%Nov 3, 2021
CVE-2020-24743: Undefined Security Weakness9.8 CriticalN/A3%Nov 3, 2021
CVE-2020-20982: Improper Neutralization of Input During Web Page Generation9.6 CriticalN/A6%Nov 3, 2021
CVE-2020-23109: Buffer Copy without Checking Size of Input8.1 HighN/A1%Nov 3, 2021
CVE-2020-23126: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A1%Nov 3, 2021
CVE-2020-5955: Undefined Security Weakness9.8 CriticalN/A1%Nov 3, 2021
CVE-2020-27820: Use After Free4.7 MediumN/A1%Nov 2, 2021
CVE-2020-16048: Out-of-bounds Read6.5 MediumN/A1%Nov 2, 2021
CVE-2020-6492: Use After Free9.6 CriticalN/A1%Nov 2, 2021
CVE-2020-15935: Cleartext Storage of Sensitive Information4.3 MediumN/A1%Nov 2, 2021
CVE-2020-12814: Improper Neutralization of Input During Web Page Generation4.1 MediumN/A0%Nov 2, 2021
CVE-2020-15940: Improper Neutralization of Input During Web Page Generation4.1 MediumN/A1%Nov 2, 2021
CVE-2020-23754: Improper Neutralization of Input During Web Page Generation9.6 CriticalN/A2%Nov 2, 2021
CVE-2020-23719: Improper Neutralization of Input During Web Page Generation9.6 CriticalN/A1%Nov 2, 2021
CVE-2020-23718: Improper Neutralization of Input During Web Page Generation9.6 CriticalN/A1%Nov 2, 2021
CVE-2020-23686: Cross-Site Request Forgery (CSRF)8.8 HighN/A1%Nov 2, 2021
CVE-2020-23685: Improper Neutralization of Special Elements used in an SQL Command9.8 CriticalN/A2%Nov 2, 2021
CVE-2020-21574: Buffer Copy without Checking Size of Input7.5 HighN/A1%Nov 2, 2021
CVE-2020-21573: Uncontrolled Resource Consumption5.5 MediumN/A1%Nov 2, 2021
CVE-2020-21572: Buffer Copy without Checking Size of Input7.5 HighN/A1%Nov 2, 2021
2576-2600 of 21077